Searching for the Cure to Healthcare Security

Searching for the Cure to Healthcare Security

Jeremy Wall • May 27, 2016
Jeremy Wall • May 27, 2016

Share

The Department of Health and Human Services (HHS) recently announced the formation of the Health Care Industry Cybersecurity Task Force, a group charged with evaluating best practices on data security, which should spur greater investment by the healthcare community in cybersecurity. According to HHS, the number of health records compromised jumped from 13 million in 2014 to 113 million in 2015.


Until last year, the majority of data breaches were due to stolen or misplaced laptops or files accessed from within the building. This is still a problem—the 750,000 people who had records stolen this way last year likely agree—but de minimis compared to the broader threat of hacking and phishing—in this case, where a cybercriminal tricks someone to provide their electronic health record (EHR) login credentials. And ransomware is the new version shut down the system in a hospital, for a fee (two public incidents in the last three months).


Healthcare technology spending ranges from $40 billion-$50 billion in the U.S., but has been concentrated in a limited number of EHR providers who no doubt, keep security as an important feature, but not the main feature of their offerings. Security itself should be amongst the next big waves—the need is there and it is not going to get better on its own. The threat environment should create significant opportunity for managed security service providers (MSSPs) and security providers willing to take the plunge into the complicated world of healthcare, and the competitive landscape has not yet matured as the top healthcare IT outsourcers and advisors are still focused on uptime and convenience. The fact that KLAS does not have an award for security services is an indicator of focus.


That said, selling into healthcare is a complicated endeavor. Particularly selling technology and services into healthcare. First, they segment into payers and providers: * Payers skew to the larger end of the enterprise spectrum. Given their size and constant need to transfer data you would expect greater sophistication, but some of the largest breaches have occurred at health plans in recent years. * Hospitals—6,000 of them—have a wide range of size and expertise and even the major hospital chains may buy individually by branch, regardless of shared services or GPOs. * Non-hospital providers—numbered in the 100s of thousands—vary dramatically by scale and need. Groups/chains tend to move together.


In our experience, when you dig into decision processes and spending patterns, both payers and providers have distinct behaviors and can be segmented further. The benefits to having a deep understanding of different segments include better ability to direct product development, sales and marketing resources. And similarly to know which partners and channels with which you’ll have the best chance of success.


For the payers, Stax’s research shows that some should be nearing the end of their investment in enterprise data warehousing and integration, and they have a lot that they need to protect. They are also comfortable outsourcing large implementations to third party providers and the sales cycle is generally slow. All this points to the opportunity to choose your end target and best partners along the way. Providers have a much more complex challenge for three primary reasons: broad range of user sophistication, broad user access, and a broader industry goal of more information sharing.


The broad range user sophistication is the largest issue facing hospitals today. More so than any other industry, access to large amounts of sensitive data is being put in the hands of many employees with low expectations on technical sophistication prior to this decade who are still in the process of learning new, often user-unfriendly, IT systems. Many of the recent provider breaches are a result of phishing scams where employees are tricked into providing login information.


The solution to this issue requires both IT departments and physicians to have the difficult discussions to flag which users are less savvy and to work with them to understand the range of potential attacks and what to do in each instance. Broad user access is not an issue that is going away any time soon, and therefore must be incrementally improved rather than eliminated. Provider IT departments must work closely with medical and HR departments to ensure that access is purely limited to those who need it, and are only able to access information required to do their job. Tiering of rights based on position, finger or palm print identification verification, and tightening the number of access points should be top of mind for providers.


Lastly, Stax’s research shows that providers are interested and investing in more remote services via telemedicine and more patient engagement, which means even more information bouncing between systems and remote access. When enabling this new communication between physicians and patients and between systems, compliance should be top of mind for all parties. Providers must work to limit the amount of information accessible across platforms to only what is required, clarify which parties are responsible for maintaining which aspects of the data, and to complete a full vetting of partner sophistication and access.


The good news is that over time we’ve been able to identify publicly available data that can be overlaid with competitive analysis and direct primary research to enable mapping the market intelligently. This begets clear answers. What’s really interesting is finding out the true opportunity set and the differential between needs of different segments—and once you know the segment—how to really spot a potential customer versus a potential sinkhole. In a similar way that cyber data researchers and scientists use big data and behavioral analyses to keep the wrong people out, one can develop a fact base and behavioral and situational analysis, to determine which customers, are most likely to want to come in.


Jeremy Wall is a director at Stax, where he provides data-driven analysis and actionable research on industry dynamics and growth strategies to management teams and investors. He works across various business sectors and specializes in using complex data to develop business cases for technology, retail, industrial, healthcare, and financial services organizations.


Read More

The Final 12 Months Before Exit: Building the Next Buyer’s Investment Case
By Paul Edwards June 11, 2026
Global Practice Leader Paul Edwards highlights the value of the final year before a sale and how investors can utilize this time to generate better outcomes. Read more.
The US Early Childhood Education Market: Growth Requires a Focused Expansion Playbook
By Miriam El-Baz & Alex Erines June 11, 2026
The US ECE market remains an attractive growth arena for operators, product and service providers, and investors. Read what insights Miriam El-Baz and Alex Erines have to share.
How Leading Events Organisers Ambitions Are Evolving Intelligence: Key Takeaways from Monetising B2B
By Florent Jarry & Bharath Venkatesh June 5, 2026
Florent Jarry and Bharath Venkatesh attended Monetising B2B a conference hosted in London in May 2026. Read their full report on their learnings here.
Feat. by ION Analytics: Hospice M&A Rebounds, Assets in Short Supply
June 4, 2026
Rob Larson was interviewed by ION Analytics to discuss the recent trends in hospice M&A and what is driving investors to make these moves. Read the full article here.
The Second Institutional Exit Has Changed: What Buyers Underwrite Today
By Paul Edwards June 3, 2026
The market for second institutional exits has become more demanding. Global Practice Leader Paul Edwards breaks down what he has observed and how companies can attract high-value buyers.
Featured by Wall Street Journal: Private Equity Looks to Consolidate HOA Management Companies
June 2, 2026
Tyler Veit was quoted in The Wall Street Journal's recent article, sharing his thoughts on the fragmentation challenges facing investors while also providing a positive outlook. Read more.
Show More